Security News
New variant of Anatsa banking trojan spotted on Android
Security researchers report a new Anatsa variant spreading through tampered PDF-reader apps in the Play Store.
Security researchers have documented a new variant of the banking trojan Anatsa. It is distributed through harmless-looking PDF reader and file manager apps that pass Play Store review and only fetch the malicious payload via an update after installation.
Anatsa targets banking apps in the DACH region, including several Swiss banks. The malware overlays the real app with fake login overlays and intercepts 2FA codes.
Protection
- Install apps only from the official Play Store – and even there, check ratings, developer, and download count
- Use a current antivirus suite with Android protection (e.g. Bitdefender or Kaspersky)
- Banking apps almost always ship a dedicated code app – use it instead of SMS codes